I am designing a RESTful API in NestJS for a project and I am struggling on how to handle the nested routes. Here is an overview:
- The authentication is handled in the frontend by Firebase. The token is sent to the API to be verified, which happens in a middleware. Upon success, the user ID from firebase is attached to the request and forwarded.
- Each user can create multiple pet profiles, living under the
/profilesendpoint. All CRUD operations are supported. - Each pet profile can have various resources related to them, notes for example.
- All of the resource types are separated by Nest modules, which contain the entity, service, etc.
Here we reach the part that I can't wrap my mind around. It would make sense to nest the resource as /profiles/:profileId/notes.
Subsequent nesting, e.g. a specific note, would be /profiles/:profileId/notes/:noteId and so on. CRUD operations would also be handled there.
What bothers me is that going with this approach, I will end up having a single controller for the entire app - the Profiles contoller.
Another approach I considered was having the GET ALL and POST methods under the Profiles controller, and GET, PUT and DELETE under a module specific controller - e.g. /notes/:noteId. But in that case I don't know how to protect those sub-resources, as I wouldn't have the profileId available this way - and I wouldn't know if the caller owns the profile, so that I can authorize those operations.
How would you handle this issue? Thanks for the replies.